Last updated - August 2018
QBE Insurance Group Limited ("QBE Group") and its affiliates ("we", "us", "our" or "QBE") adhere to this Privacy Statement ("Statement") in respect of our collection, use and disclosure of personal information. This is our external privacy notice which applies to all information collected over this website https://www.qbe.com. For all other information collected by QBE, the privacy practices of each QBE entity will be explained in separate privacy policies which are made available to you when you first contact us and when your personal information is first collected by that relevant QBE entity.
For more information on the privacy practices and policies of the QBE Group entity in your region, please see:
Asia Pacific - http://www.qbeap.com/privacy-policy.html
This website is operated by QBE Insurance (Australia) Limited who will, for the purposes of relevant data protection laws (including the EU General Data Protection Regulation (GDPR)), be the primary controller of your personal data.
The QBE entity responsible for your personal information will be the member of QBE that first collects information from or about you; for example, for information collected on other QBE websites, the QBE entity operating the relevant website will be your data controller; if you are a supplier, the QBE entity to whom you provide services will be your data controller.
What is the purpose of this Statement?
Please read this statement carefully. It explains how we collect, use and share personal information when we collect it from you, including:
- What personal information we collect and when and why we use it.
- How we share personal information within QBE and with our service providers, regulators and other third parties
- Explaining more about Direct Marketing
- Transferring personal information globally
- How we protect and store personal information
- Legal rights available to help manage your privacy
- How you can contact us for more support
We may amend this Statement from time to time and will place any updates on this webpage. Please regularly check these pages for the latest version of this Statement. If we make fundamental changes to this Statement, we will seek to inform you by notice on our website or email.
Our websites may contain links to third party sites. Since QBE does not control nor is responsible for the privacy practices of those websites, we encourage you to review the privacy policies of these third-party sites. This Statement applies solely to personal information collected by our website.
WHAT PERSONAL INFORMATION WE COLLECT AND WHEN AND WHY WE USE IT
Persons We Collect Information From
Primarily, we collect personal information from the following categories of persons who may visit our website:
- individual representatives (employees, directors, members etc.) of the companies, firms or other organisations who are our prospective and current customers and/or suppliers
- prospective, current and former investors and shareholders of QBE
- visitors to our website
Personal information we collect automatically and use if you use our website
When you visit the website, our server automatically collects certain browser or device generated information, including but not limited to your:
- IP address;
- date, time and duration of your visit;
- browser type;
- operating system; and
- page visits.
We may use this automatically collected information for aggregated analytical purposes but we do not use it to try to uniquely identify you as an individual and we do not associate it with the information you provide voluntarily. However, we may use this information to associate you with the organisation you work for, or to understand the approximate geographic area may be visiting the website from.
Personal information we collect and use if you provide it to us
If you are an investor in QBE, you will have provided basic personal information when subscribing for shares in QBE.
In using our website, you may voluntarily provide personal information to us in the following ways:
- by signing up for news alerts (including those from any of our third party partners where we notify you and you confirm in advance), newsletters or other forms of communication;
- by registering for an event or webinar;
- by corresponding with us by phone, e-mail or otherwise using the contact details provided on our website;
- when making an enquiry with us.
Typically, the personal information you give us may include your name, address, e-mail address, phone number, and any personal details required to resolve any inquiry. See more on our marketing activities below.
Legal basis for using your personal information
The following is an overview of our purposes for using your personal information. Please remember that additional information may be provided to you in a separate notice or contract or where you access any of our other websites or online products or services. We will only collect, use and share your personal information where we are satisfied that we have an appropriate legal basis to do this. This may be because:
- you have consented to the processing (for example, where you consent to the placing of cookies on our websites, or where you proactively sign-up for a QBE newsletter);
- we need to use your personal information for our legitimate interest as a commercial organisation subject to your interests and fundamental rights (which will apply to the majority of our activities under this Statement; for example, we have a legitimate commercial interest in building good relations with our customers, suppliers, investors and shareholders by providing information them on the services we provide, the activities of QBE, by maintaining customers, suppliers, investors and shareholder relationship management databases, by sharing information intra-group and by contacting our customers, suppliers investors and shareholders from time to time); or
- we need to use your personal information to comply with a relevant legal or regulatory obligation that we have.
If you would like to find out more about the legal basis for which we process personal information please contact us.
We use the personal information we collect to:
- allot shares, maintain a register of our shareholders and members, and communicate with those members (through reports, meetings etc.)
- improve our websites based on how you and other users interact with our content;
- customise or personalise our websites to users' needs (for example, by showing content or language which is relevant to your geographic location);
- correspond with website users to resolve their queries or complaints; and
- send you marketing communications (e.g. newsletters), where it is lawful for us to do so.
SHARING PERSONAL INFORMATION WITH OTHERS
We share your personal information in the manner and for the purposes described below:
- within QBE Group, where such disclosure is necessary to provide you with our products or and services and/or to manage our business;
- with third party service providers (who will operate under our instructions) who help manage our business and assist us in providing information or services to you (for example, suppliers of relationship management or marketing solutions or third party IT service providers to manage and improve the website. These third parties may need access to your information and will have agreed to confidentiality restrictions and obligations to use any personal information we share with them or which they collect on our behalf solely for the purpose of providing the contracted service to us; or
- with government organisations and agencies, law enforcement and regulators if needed to comply with all applicable laws, regulations and rules, and requests of law enforcement, regulatory and other governmental agencies.
If, in the future, we sell or transfer some or all of our business or assets to a third party, we may disclose information to a potential or actual third party purchaser of our business or assets.
TRANSFERRING PERSONAL INFORMATION GLOBALLY
QBE is a group with affiliates, divisions and offices situated throughout the world, and it will therefore be necessary, from time to time, to pass your information between QBE locations internationally. A full list of our locations is available here: https://www.qbe.com/about-qbe
Accordingly, your personal information may be transferred and stored in regions and countries outside the EU or your country of residence, including Australia, Asia Pacific, New Zealand, Pacific Islands, India, North America and within Europe, including QBE's services company located in the Philippines which provides sales, claims administration and other services to the Group, and/or to any other countries where QBE entities operate or may operate in the future, each of which may be subject to different standards of data protection to your country of residence.
We will take appropriate steps ensure that transfers of personal information are in accordance with applicable law and carefully managed to protect your privacy rights and interests and transfers are limited to countries which are recognized as providing an adequate level of legal protection or where we can be satisfied that alternative arrangement are in place to protect your privacy rights. To this end:
- we will ensure any transfers within QBE Group are covered by an agreement entered into by members of QBE (an intra group data transfer agreement) which contractually obliges each member of QBE to ensure that personal information receives an adequate and consistent level of protection wherever it is transferred within QBE (this agreement will incorporate the EU Commission approved Standard Contractual Clauses, where needed to ensure that EU personal information receives the same level of protection as if it remained within the EEA). We may also rely on certification schemes, such as the EU - US Privacy Shield, or other mechanisms provided for by all applicable privacy laws to ensure any personal information transferred within our group of companies complies has adequate safeguards and is compliant with such laws;
- if / where we transfer your personal information outside QBE or to third parties who help provide our products and services, we obtain contractual commitments from them to protect your personal information in accordance with all applicable privacy laws ; or
- where we receive requests for information from law enforcement or regulators or when required to do so by law, we carefully validate these requests before any personal information is disclosed.
You have a right to contact us for more information about the safeguards we have put in place (including a copy of relevant contractual commitments) to ensure the adequate protection of your personal information when transferred overseas.
EXPLAINING MORE ABOUT DIRECT MARKETING
How we use personal information to keep you up to date with our products and services
We may use personal information to let you know about our products and services that we believe will be of interest to you (for example, where you have signed up for one of our newsletters). We may contact you by email, post, or telephone or through other communication channels that we think you may find helpful. In all cases, we will respect your preferences for how you would like us to manage marketing activity with you.
How you can manage your marketing preferences
To protect privacy rights and to ensure you have control over how we manage marketing with you:
- we will take steps to limit direct marketing to a reasonable and proportionate level and only send you communications which we believe may be of interest or relevance to you;
- you can ask us to stop direct marketing at any time you can ask us to stop sending marketing, by following the "unsubscribe" link you will find on all the email marketing messages we send you. Alternatively you can contact us at https://www.qbe.com/contact-us. Please specify whether you would like us to stop all forms of marketing or just a particular type (e.g. email); and
- you can change the way your browser manages cookies, which may be used to deliver online advertising, by following the settings on your browser as explained in the Cookies section of this Privacy Statement.
We recommend you routinely review the privacy policies or notices and preference settings that are available to you on any social media platforms as well as your preferences within your account with us.
HOW WE PROTECT AND STORE YOUR INFORMATION
We take the security of the information we collect seriously. We have implemented and maintain technical and organisational security measures, policies and procedures designed to reduce the risk of accidental destruction or loss, or the unauthorised disclosure or access to such information appropriate to the nature of the information concerned.
Measures we take include:
- placing confidentiality requirements on our staff members and service providers;
- following strict security procedures in the storage and disclosure of your personal information to prevent unauthorised access to it; and
- using secure communication transmission software (such as "transport layer security" or "TLS") that encrypts all information you input on our website before it is sent to us. TSL is an industry standard encryption protocol for the financial services industry (recommend by PCI DSS and relevant regulators) and this ensures that the information is reasonably protected against unauthorized interception.
However, in relation to our website, it is important to remember that no website can be 100% secure and we cannot be held responsible for unauthorised or unintended access that is beyond our control. As the security of information depends in part on the security of the computer you use to communicate with us and the security you use to protect User IDs and passwords, please take appropriate measures to protect this information.
Storing your personal information
We will store your personal information in electronic and hardcopy and for as long as is reasonably necessary for the purposes for which it was collected, as explained in this privacy statement. We maintain a data retention policy which we apply to records in our care. Where your personal information is no longer needed, we will ensure that it is deleted and disposed of in a secure manner.
In some circumstances we may store your personal information for longer periods of time, for instance where we are required to do so in accordance with legal, regulatory, tax, accounting requirements (for example, certain records are kept for 7 years after the completion of a policy or claim).
Where we have obtained your personal information in order to provide you with marketing information for our products and services (including QBE newsletters), your personal information will be stored by us only as long as you do not change your mind to receive such materials from QBE, in order to avoid future contact with you for marketing purposes.
In other specific circumstances we may store your personal information for longer periods of time so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your personal information or dealings.
A cookie is a small text file containing small amounts of information which is downloaded to / stored on your computer (or other internet enabled devices, such as a smartphone or tablet) when you visit a website.
LEGAL RIGHTS AVAILABLE TO HELP MANAGE YOUR PRIVACY
You may access or request correction of the personal information that we hold about you by contacting us. There are some circumstances in which we are not required to give you access to your personal information. There is no charge for requesting access to your personal information but we may require you to meet our reasonable costs in providing you with access (such as photocopying costs or costs for time spent on collating large amounts of material).
Subject to certain exemptions, and in some cases dependent upon the processing activity we are undertaking, where EU laws apply, you have certain rights in relation to your personal information.
If you wish to access any of the rights detailed in this section, we may ask you for additional information to confirm your identity and for security purposes, in particular before disclosing personal information to you. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive.
You can exercise your rights by contacting us. Subject to legal and other permissible considerations, we will make every reasonable effort to honour your request promptly or inform you if we require further information in order to fulfil your request.
We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way.
Under EU laws, some of the following rights may be available to you:
Right to access personal information
You have a right to request that we provide you with a copy of your personal information that we hold and you together with how and on what basis your information is processed.
Right to rectify or erase personal information
You have a right to request that we rectify inaccurate personal information. We may seek to verify the accuracy of the personal information before rectifying it.
You can also request that we erase your personal information in limited circumstances where
- it is no longer needed for the purposes for which it was collected;
- you have withdrawn your consent (where the data processing was based on consent - for example where you have provided your consent to receive marketing newsletters, you can withdraw this consent at any time);
- following a successful right to object (see right to object);
- it has been processed unlawfully; or
- to comply with a legal obligation to which QBE is subject.
We are not required to comply with your request to erase personal information if the processing of your personal information is necessary:
- for compliance with a legal obligation; or
- for the establishment, exercise or defense of legal claims.
Right to restrict the processing of your personal information
You can ask us to restrict your personal information, but only where:
- its accuracy is contested, to allow us to verify its accuracy;
- the processing is unlawful, but you do not want it erased;
- it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise or defend legal claims; or
- you have exercised the right to object, and verification of overriding grounds is pending.
We can continue to use your personal information following a request for restriction, where:
- we have your consent;
- to establish, exercise or defend legal claims; or
- to protect the rights of another natural or legal person.
Right to transfer your personal information
You can ask us to provide your personal information to you in a structured, commonly used, machine readable format, or you can ask to have it transferred directly to another data controller, but in each case only where:
- the processing is based on your consent or on the performance of a contract with you; and
- the processing is carried out by automated means.
Right to object to the processing of your personal information
You can object to any processing of your personal information which has our legitimate interests as its legal basis, if you believe your fundamental rights and freedoms outweigh our legitimate interests.
If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.
Right to object to how we use your personal information for direct marketing purposes
You can request that we change the manner in which we contact you for marketing purposes.
You can request that we not transfer your personal information to unaffiliated third parties for the purposes of direct marketing or any other purposes.
Right to obtain a copy of personal information safeguards used for transfers outside your jurisdiction
You can ask to obtain a copy of, or reference to, the safeguards under which your personal information is transferred outside of the European Union. We may redact data transfer agreements to protect commercial terms.
Right to lodge a complaint with your local supervisory authority
You have a right to lodge a complaint with your local supervisory authority if you have concerns about how we are processing your personal information. If you are in Australia, you may contact the Office of the Australian Information Commissioner (www.oaic.gov.au) for guidance.
We ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time.
For all issues arising from this privacy Statement please contact us at https://www.qbe.com/contact-us.
If you have any questions, concerns or complaints regarding our compliance with this Statement, the information we hold about you or if you wish to exercise your rights, we encourage you to first contact us. We will investigate and attempt to resolve complaints and disputes and make every reasonable effort to honour your wish to exercise your rights as quickly as possible and in any event, within the timescales provided by applicable data protection laws.